Skip to content
DnsLister Forum

Where domain hunters compare notes

2026-08-09: Traffic Analysis Exercise – First to Last

This is a great practical exercise for sharpening network forensics skills.

The site provides a full PCAP from a real infection chain, starting with the initial compromise and ending with the final payload execution. The exercise is unlabeled, meaning you have to work through the traffic yourself to identify the malware family, C2 infrastructure, and data exfiltration methods.

What you’ll be looking for:

  • Initial Access: Likely a phishing lure or drive-by download. Expect HTTP/HTTPS requests to suspicious domains, often with user-agent strings that don’t match the browser.
  • C2 Beaconing: Periodic GET/POST requests to low-reputation IPs or domains. Look for patterns in timing (e.g., 60-second intervals) and URI paths (e.g., /images/, /gate.php).
  • Payload Delivery: Binary downloads over HTTP or embedded in TLS streams. Check for executable MIME types or unusual file extensions (.scr, .ps1, .vbs).
  • Exfiltration: DNS tunneling, HTTP POST with base64-encoded data, or SMB traffic to unusual external IPs.

Defense angle: This is a great training dataset for your SOC analysts. Run it through your IDS/NSM (Suricata, Zeek) and see if your rules catch the beaconing. If not, it’s a signal to tune your detection logic for the specific TTPs used in this campaign.

Source: https://www.malware-traffic-analysis.net/2026/08/09/index.html

submitted by /u/falconupkid to r/SecOpsDaily
[link] [comments]

Source: r/SecOpsDaily · by /u/falconupkid

Leave a Reply

Your email address will not be published. Required fields are marked *